A Kubernetes cluster role was created
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
Requires one of the following data sources: AWS Audit Log OR Azure Audit Log OR Gcp Audit Log OR Kubernetes Audit Logs
Detection Modules
Cloud
Detector Tags
Kubernetes - API
ATT&CK Tactic
Persistence (TA0003), Privilege Escalation (TA0004)
ATT&CK Technique
Account Manipulation: Additional Container Cluster Roles (T1098.006)
Severity
Informational
Description
A Kubernetes cluster role was created.
Attacker's Goals
Create overpermissive cluster roles to escalate privileges within the Kubernetes cluster.
Investigative actions
Check the permissions granted to the newly created Kubernetes cluster role.
Check whether this cluster role was bound to an identity via a ClusterRoleBinding or RoleBinding.
Verify whether the identity that created the cluster role is authorized to perform RBAC operations.
Review subsequent API calls made by the same identity for signs of privilege escalation or lateral movement.
Variations
Was this helpful?
